Eve Goode, Digital Content Editor speaks with Nick Reed, Chief Strategy Officer of Bizzdesign about the new EU Tech Sovereignty Package.
What does the EU’s new Tech Sovereignty Package mean for enterprise IT leaders, and why is it such a significant development?
The Tech Sovereignty Package, formally proposed by the European Commission on 3 June 2026, is the EU’s direct response to the risks around digital dependency, which it now treats as a strategic vulnerability.
EU organisations currently rely on non-EU countries for over 80% of key digital products, services, infrastructure and intellectual property, and EU cloud providers have seen their regional market share fall from 29% in 2017 to 15% in 2022, where it has remained flat.
The package covers cloud and AI, open source, semiconductors and energy digitalisation.
For enterprise IT leaders, the most immediately relevant element is the Cloud and AI Development Act, which introduces a single EU-wide cloud sovereignty framework and requires public sector bodies to carry out sovereignty risk assessments.
Private companies in sectors of high criticality such as energy, transport, healthcare and finance should also be paying attention, as the framework could extend to how they procure cloud services in the future.
What makes this significant is the shift it represents. Previous EU technology regulation has largely focused on how technology is used.
This package focuses on who controls it, and that changes the entire supply chain and architecture decisions of organisations operating within the European market.
This means it could potentially have a very significant impact on IT landscapes for European organisations.
The package still has to pass through the European Parliament and Council, where further changes are likely and once finalised organisations will have a year to implement.
Those that start mapping their activities against the sovereignty framework now, adjusting as the detail evolves, will be in a stronger position when the obligations come into force.
Do you expect the new sovereignty requirements to boost the adoption of European cloud providers, and what factors will influence those decisions?
The market for sovereign cloud is projected to reach €100 billion in Europe by 2031[NR1], but whether that demand flows exclusively to European providers is a more complicated question.
Current geopolitical uncertainty is pushing organisations across Europe to seek greater assurance over who controls their data and operations.
The EU Cloud Sovereignty Framework, published by the European Commission in October 2025 as a procurement methodology, addresses that directly, assessing providers across eight sovereignty objectives: strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability.
When the Commission applied this framework to its own €180 million tender in April 2026, it awarded contracts to four “EU-sovereign” providers, yet one of those incorporated US cloud infrastructure via a consortium integrating Google Cloud infrastructure via a Thales joint venture (S3NS).
It qualified on the basis of its technical and operational controls, not its corporate origin.
What will ultimately influence those decisions comes down to a few key factors:
- Regulatory environment: Obligations differ by jurisdiction and sector, and the right answer for one organisation won’t be the right answer for another
- Data classification: Which workloads process sensitive or regulated data, and what level of sovereignty that requires under the applicable framework
- Sovereignty objectives: Which of the eight dimensions matter most for a given organisation, and which providers can demonstrate the right assurance level across those specific dimensions
- Total cost of transition: Migration costs, vendor lock-in and operational continuity all factor into the decision alongside compliance requirements
- Provider capability: whether a provider can evidence the required controls at the workload level, rather than relying on a general certification
Sovereignty requirements are accelerating the conversation, but the decisions themselves will be made workload by workload.
What information do CIOs need to know before making cloud repatriation or migration decisions?
Before any decision is made, CIOs need to understand how much sovereignty each workload requires and across which dimensions.
The EU Cloud Sovereignty Framework provides a structured way to work through that, assessing providers against eight sovereignty objectives, each scored on a five-point scale called the Sovereignty Effectiveness Assurance Level or SEAL, running from SEAL-0, no sovereignty, to SEAL-4, full digital sovereignty.
The objectives cover strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability.
The legal and jurisdictional dimension deserves particular attention because if the laws are in place but you can’t enforce them, you’re not protected.
Scoring each workload against those dimensions tells you where the regulatory gaps are, but CIOs also need to understand what closing those gaps would involve in practice.
A workload might need to move to meet a sovereignty requirement, but if it has multiple application dependencies or serves a critical customer function, the migration looks very different than if it were isolated.
Before committing to anything, CIOs need visibility into:
- Application dependencies
- Data flows and classifications
- Third-party suppliers and cloud dependencies
- Business criticality
- Migration costs and timelines
- Potential customer and operational impacts
Without that full picture, organisations risk either overspending on migrations they didn’t need or underestimating the regulatory and operational exposure they set out to address.
What you’re working toward is a workload-by-workload assessment that balances sovereignty requirements against the true total cost of migration, grounded in a clear view of what the supply chain looks like.
Looking ahead, how can enterprises balance regulatory compliance, innovation and operational resilience?
Innovation requires speed and open collaboration with partners who can move at the same pace. Regulatory compliance and operational resilience pull in the opposite direction, demanding control, auditability and the ability to demonstrate that your supply chain meets your obligations.
The degree of tension between those things depends heavily on where you operate.
In the EU, NIS2 sets out specific and binding requirements across critical sectors, including supply chain risk management, incident reporting within strict timeframes, and audit rights over critical suppliers.
DORA adds further obligations for financial entities, requiring operational resilience testing, ICT supplier auditability and specific contractual provisions with critical technology providers.
The UK operates differently, with a principles-based model that focuses on keeping critical business services running rather than specifying how that’s achieved.
Regardless of jurisdiction, the direction of travel is clear enough that every organisation should be asking itself whether it can continuously demonstrate control over its critical business services.
Those that can answer that confidently tend to find the broader compliance challenge more manageable, because they’ve already done the work of defining what sufficient control means for their context rather than trying to achieve maximum control across the board, which is costly and rarely achievable in practice.
When organisations build a connected picture of how their critical services depend on applications, data, technology and third parties, they can manage compliance obligations from a single foundation rather than running separate programmes for each framework.
That clarity gives teams the room to innovate within well-defined boundaries rather than navigating dozens of overlapping compliance checklists covering the same assets.
Resilience follows the same logic, treated as a continuous operational capability rather than siloed exercises.